Executive summary
Regulation (EU) 2024/1689, known as the EU AI Act, published in the Official Journal of the European Union on 12 July 2024 and in force since 1 August 2024, establishes the world's first horizontal and binding framework for the artificial intelligence market.
Based on Article 114 of the Treaty on the Functioning of the European Union (TFEU), the Regulation pursues a twofold goal: to foster the growth of trustworthy, ethical and human-centric AI within the EU single market, and to guarantee a high level of protection for health, safety and the fundamental rights enshrined in the EU Charter of Fundamental Rights.
Adopting a risk-based approach, the AI Act calibrates obligations according to the potential harmfulness of algorithmic applications. For public and private organisations, regulatory alignment goes beyond the purely legal dimension: it calls for a genuine Artificial Intelligence Management System (AIMS) integrated with data protection governance (GDPR) and cybersecurity governance (NIS2 / ISO/IEC 27001).
01Scope and qualification of actors
1.1 Territorial and extraterritorial scope (Art. 2)
Mirroring the GDPR model, the AI Act adopts a principle of extended extraterritoriality. The rules apply to:
- Providers: entities that develop an AI system or a general-purpose model (GPAI) and place it on the market or put it into service under their own name or trademark in the EU, whether established in the EU or in a third country.
- Deployers (professional users): public or private entities established or located in the EU that use AI systems in the course of their professional activity.
- Providers and deployers in third countries: where the output produced by the system is used within the European Union.
- Importers and distributors: operators that make available on the EU market systems developed outside the Union.
- Product manufacturers that integrate AI systems as safety components in goods regulated by EU harmonisation legislation.
1.2 Express exclusions from scope
The following fall outside the Regulation: systems developed or used exclusively for military, defence or national-security purposes; scientific research, development and prototyping prior to placing on the market (except for testing in real-world conditions); systems used by natural persons for purely personal, non-professional activities; models released under free and open-source licences, save for the exceptions applying to high-risk systems, GPAI models with systemic risk and prohibited applications.
1.3 Legal definition of an AI system (Art. 3(1))
Under the Regulation, an AI system is defined as "a machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments."
1.4 Value-chain operators and allocation of responsibilities (Arts. 23, 24, 25)
Beyond providers and deployers, the Regulation governs the other operators in the chain. Before making a high-risk system available on the market, the importer (Art. 23) and the distributor (Art. 24) must verify that the conformity assessment has been carried out, that the system bears the CE marking, the declaration of conformity and the required documentation, and that the provider has appointed an authorised representative where necessary; if they consider the system non-conforming they may not place it and must inform the authorities.
Article 25 sets out when a distributor, importer, deployer or third party takes on the provider's obligations in full (Art. 16). This happens when: they put their name or trademark on a high-risk system already placed on the market, unless otherwise contractually allocated; they make a substantial modification that keeps it high-risk; or they modify the intended purpose of a system, including a general-purpose AI system, not classified as high-risk in such a way that it becomes high-risk. In these cases the original provider is relieved of the obligations but must cooperate and provide the necessary information, except for tools released under a free and open-source licence. For safety components of already regulated products, the product manufacturer takes on the provider role.
Watch out when using GPAI and third-party systems. A deployer that customises, retrains or repurposes a third-party model or system may become its provider, with all the related obligations. It is essential to define the allocation of responsibilities along the value chain by contract.
02Risk taxonomy and regulatory classification
The Regulation splits AI applications into four risk tiers, each with graduated rules: unacceptable risk (Art. 5, prohibited practices), high risk (Arts. 6-49, Annexes I and III, ex-ante conformity assessment, QMS, CE marking), specific/transparency risk (Art. 50) and minimal or no risk (Art. 95).
2.1 Tier 1: unacceptable risk, prohibited practices (Art. 5)
Article 5 exhaustively lists the practices whose placing into service or use is strictly prohibited across the Union:
- Subliminal and deceptive manipulation: systems that materially distort human behaviour, impairing informed decision-making and causing significant harm.
- Exploitation of vulnerabilities linked to age, disability or socio-economic conditions in order to alter behaviour and cause harm.
- Social scoring: assessing the trustworthiness of people based on social behaviour or personal characteristics, leading to unjustified detrimental treatment.
- Individual predictive policing based solely on profiling, without verifiable objective facts.
- Untargeted facial scraping: building facial-recognition databases through untargeted extraction from the internet or CCTV.
- Emotion recognition in the workplace and in education, save for medical or safety reasons.
- Sensitive biometric categorisation to infer political, religious, trade-union, sexual orientation or race.
- "Real-time" remote biometric identification in publicly accessible spaces, prohibited for law-enforcement purposes save for very limited judicial exceptions.
2.2 Tier 2: high risk (High-Risk AI Systems)
A system is classified as high risk along two paths (Art. 6): A) safety components of harmonised products subject to conformity assessment (Annex I: medical devices, civil aviation, machinery, lifts, gas appliances, toys); B) "stand-alone" systems in critical areas (Annex III): biometrics, critical infrastructure, education and vocational training, employment and workforce management (HR), access to essential services (credit, insurance, emergency response), law enforcement/migration/asylum/borders, administration of justice.
The Art. 6(3) exemption is not automatic. A system listed in Annex III is not deemed high risk if it does not pose a significant risk to health, safety or fundamental rights (narrow procedural tasks, improving a human activity without replacing it, detecting anomalies without autonomous decisions). The provider must, however, document the assessment justifying the exemption and, in the cases set out in Art. 6(4), register the system in the EU database before putting it into service. Failure to document still exposes the provider to challenge by the supervisory authority.
2.3 Tier 3: specific risk, transparency obligations (Art. 50)
Deployers and providers must ensure that people are clearly informed when they are interacting with an AI system (chatbots, voice assistants), unless it is obvious. Providers of synthetic-generation systems (generative AI, deepfakes) must ensure outputs are marked in a machine-readable format (watermark) and labelled as artificial. Synthetic content published to inform the public on matters of general interest must carry a notice about its artificial origin.
2.4 Tier 4: minimal or no risk (Art. 95)
All other systems (spam filters, video games, optimisation of non-critical internal logistics) carry no binding obligations; the Union encourages the voluntary adoption of codes of conduct.
03General-purpose AI models (GPAI)
The AI Act introduces a dedicated framework for General Purpose AI (GPAI), i.e. foundation models such as LLMs and multimodal generators, distinguishing between base models and models with systemic risk (Arts. 51-56).
| Type | Regulatory obligations |
| Ordinary GPAI (e.g. standard provider LLMs) | Transparency of technical documentation; compliance with EU copyright law; publication of a sufficiently detailed summary of the data used for training. |
| GPAI with systemic risk (cumulative compute > 10²⁵ FLOPs) | All ordinary GPAI obligations, plus: advanced model evaluation (testing); assessment and mitigation of systemic risks (e.g. cyber-offensive, chemical); adversarial red teaming; reporting of serious incidents to the AI Office; a high level of cybersecurity. |
The 10²⁵ FLOPs threshold (Art. 51) is a presumption of systemic risk, not a fixed limit: the European Commission may update it via delegated acts and may also designate as systemic a model below the threshold, based on other criteria (number of users, potential impact). It should be treated as a current reference parameter, not an immutable threshold.
04Requirements for high-risk systems (Chapter III, Arts. 9-15)
Providers of high-risk systems must implement rigorous ex-ante architectural and organisational compliance before placing the system on the market.
- Art. 9, Risk management system: a continuous and iterative process across the entire lifecycle: identification and analysis of known and foreseeable risks to health, safety and fundamental rights; estimation of risks from intended use or reasonably foreseeable misuse; measures to eliminate or reduce residual risks to an acceptable level.
- Art. 10, Data & data governance: training, validation and testing datasets must meet verifiable quality criteria: governance of provenance, selection, cleaning, enrichment and annotation; assessment and mitigation of bias; relevance, representativeness, freedom from errors and completeness with respect to the operating context.
- Arts. 11-12, Technical documentation and traceability: detailed technical documentation (Annex IV) before placing on the market; automatic logging capabilities for traceability across the entire lifecycle.
- Art. 13, Transparency and instructions for use: design geared to maximum intelligibility (explainability); instructions with the provider's identity and contacts, performance characteristics and limits, known circumstances that may lead to bias or malfunction, human control and technical maintenance.
- Art. 14, Human oversight: the system must allow competent people to oversee its operation, understand its capabilities and limits, stay aware of automation bias, correctly interpret outputs, and decide at any time not to use it, disregard its output or halt its execution (stop button).
- Art. 15, Accuracy, robustness and cybersecurity: a high and consistent level of accuracy and resilience, technical robustness and advanced protection against adversarial attacks, data poisoning and prompt injection.
Once the requirements of Articles 9-15 are met, before placing the system on the market the provider must complete the conformity assessment procedure under Article 43: internal control (Annex VI) for most Annex III systems, or an assessment involving a notified body (Annex VII) in the cases foreseen, including certain biometric systems.
- EU declaration of conformity (Art. 47): the provider draws up and keeps a written declaration attesting compliance with the Regulation and makes it available to the authorities for ten years.
- CE marking (Art. 48): affixing the CE marking of conformity visibly, legibly and indelibly before entry into service; for digital systems it may be affixed electronically.
- Registration in the EU database (Arts. 49 and 71): Annex III high-risk systems must be registered in the public EU database, managed by the Commission under Article 71, before entry into service or placing on the market, to ensure transparency and traceability.
Where the system undergoes substantial modification during its lifecycle, the conformity assessment must be reviewed and, if necessary, repeated.
05Deployer obligations and the FRIA
While most design requirements fall on providers, deployers are subject to specific operational responsibilities (Arts. 26-27).
5.1 Operational obligations of the deployer (Art. 26)
- Use the system in accordance with the provider's instructions for use.
- Assign competent, trained people to human oversight (Art. 14).
- Ensure input data is relevant and representative of the intended purpose.
- Continuously monitor operation and promptly inform the provider of any risks or serious incidents.
- Retain automatically generated logs for at least 6 months, unless otherwise required by law.
- Inform worker representatives and employees before putting a high-risk system into service in the workplace.
- AI Literacy (Art. 4): ensure that staff involved in the use of AI systems have an adequate level of algorithmic literacy.
5.2 Fundamental Rights Impact Assessment (FRIA, Art. 27)
Before putting into service a high-risk system listed in Annex III, public bodies and private entities providing public services (as well as those running credit scoring and insurance systems) must carry out a FRIA, covering: a description of the business processes involved; the intended period and frequency of use; the categories of people potentially affected; specific risks of harm to fundamental rights; the human-oversight plan; mitigation measures should the risks materialise.
FRIA and DPIA should be integrated. Where a data protection impact assessment (DPIA under Art. 35 GDPR) is already required, the FRIA should be conducted jointly to avoid operational duplication.
5.3 Post-market monitoring (Art. 72)
After a system is placed on the market, the provider must establish and document a post-market monitoring system proportionate to the nature of the AI system and its risks (Art. 72). The system actively and systematically collects, documents and analyses performance data throughout the entire lifecycle, so as to verify continued compliance with the Chapter III requirements and to detect emerging risks promptly. Data may come from deployers, from the provider's own sources and from interaction with other systems.
Post-market monitoring integrates with the obligation to report serious incidents to the supervisory authorities (Art. 73) and with the deployer's operational obligations described in Section 5.1, which require the deployer to monitor operation and promptly inform the provider of any risks or incidents.
06Institutional governance architecture
The AI Act sets out a multi-level architecture: the European Commission; the European AI Office (established within the Commission, with direct supervisory and enforcement powers over GPAI model providers); the European Artificial Intelligence Board (EAIB), one representative per Member State; the Advisory Forum (stakeholders/industry); the Scientific Panel (independent experts).
Italian governance setup (Law No. 132 of 23 September 2025)
Law 132/2025, published in the Official Gazette on 25 September 2025 and in force since 10 October 2025, sets out a dual architecture: ACN (the National Cybersecurity Agency) is the market surveillance authority for the AI Act in Italy, responsible for inspections and penalties and the single point of contact with EU institutions; AgID (the Agency for Digital Italy) is the notifying authority, competent for the notification, assessment, accreditation and monitoring of conformity assessment bodies, as well as for promoting the development of AI.
The powers of sectoral supervisory authorities such as Banca d'Italia, CONSOB and IVASS remain in place within their respective remits (Art. 74(6) of the Regulation), together with the powers of the Data Protection Authority (Garante) over the processing of data in AI systems, and the powers of AGCOM as Digital Services Coordinator. A coordination committee at the Presidency of the Council of Ministers ensures alignment among the authorities involved.
Member States must also set up at least one regulatory sandbox at national level (Art. 57) to allow development, testing and validation of innovative systems under the authority's direct supervision, before placing on the market.
Regulatory sandboxes and testing in real-world conditions (Arts. 57-63)
Chapter VI establishes AI regulatory sandboxes. Each Member State ensures at least one national sandbox (Art. 57), a controlled environment that facilitates the development, training, testing and validation of innovative systems for a limited period, under the supervision of the competent authority and with guidance, checks and a final exit report. Article 59 allows, under strict conditions, the further processing of lawfully collected personal data for the public-interest development of certain systems within the sandbox.
Outside the sandboxes, Articles 60 and 61 permit testing of high-risk systems in real-world conditions, subject to a testing plan and the informed consent of the subjects involved. Article 62 introduces specific measures for SMEs and start-ups: priority access to sandboxes, awareness and training activities, dedicated communication channels, and conformity-assessment fees proportionate to the size of the undertaking, the market and the stage of development. These are particularly relevant tools for organisations that want to innovate while staying compliant.
07Penalty regime and interplay with other regulations
7.1 Framework of administrative fines (Art. 99)
Infringements carry fines calculated on the fixed amount or the percentage of total worldwide annual turnover of the previous financial year, applying the higher amount for ordinary undertakings or the lower amount for SMEs and start-ups (Art. 99(6)):
| Type of infringement | Maximum fine (ordinary undertakings) | Maximum fine (SMEs/start-ups) |
| Breach of the prohibitions (Art. 5) | Up to €35,000,000 or 7% of worldwide turnover (whichever is higher) | Up to €35,000,000 or 7% of turnover (whichever is lower) |
| Non-compliance with high-risk (Chapter III) and GPAI obligations | Up to €15,000,000 or 3% of worldwide turnover (whichever is higher) | Up to €15,000,000 or 3% of turnover (whichever is lower) |
| Incorrect or misleading information to authorities | Up to €7,500,000 or 1% of worldwide turnover (whichever is higher) | Up to €7,500,000 or 1% of turnover (whichever is lower) |
Cumulative penalties with the GDPR: AI Act fines do not rule out those for failing to comply with personal-data protection. A non-compliant high-risk system based on unlawful data processing (e.g. HR profiling without a legal basis) is exposed to cumulative fines under both Art. 99 of the AI Act and Art. 83 of the GDPR.
7.2 Integration with the ISO/IEC 42001 standard (AIMS)
To demonstrate compliance, ISO has published the ISO/IEC 42001:2023 standard (Artificial Intelligence Management System), which offers a documented structure to formally meet the Regulation's requirements:
| AI Act requirement | ISO/IEC 42001 control / sub-clause |
| Risk management system (Art. 9) | Clause 6.1 (Actions to address risks); Control A.6 (AI Risk Assessment) |
| Data governance (Art. 10) | Control A.7 (Data for AI systems); A.7.2 (Data Quality & Provenance) |
| Technical documentation (Art. 11) | Clause 7.5 (Documented information); Control A.5 (AI Policy & System Lifecycle) |
| Human oversight (Art. 14) | Control A.8.4 (Human oversight mechanisms) |
| Cybersecurity & robustness (Art. 15) | Control A.8.2 (System Security & Robustness) |
Methodological caveat. The numbering of clauses and Annex A controls may differ between drafts and the final certifiable text of ISO/IEC 42001:2023. This mapping is indicative, useful for setting up the compliance programme; before any contractual use, in a Statement of Applicability or for a certification audit, each reference should be validated against the full, up-to-date text held by the certification body.
7.3 Rights of affected persons and channels of redress (Arts. 85-87)
Section 4 of Chapter IX grants natural persons a set of remedies. Under Article 85, any person with grounds to consider that the Regulation has been infringed may lodge a complaint with the relevant market surveillance authority (in Italy, the ACN). Article 86 introduces the right to explanation of individual decision-making: a person subject to a decision taken by a deployer on the basis of the output of a high-risk system listed in Annex III, producing legal effects or similarly significantly affecting them in a way they consider adverse to their health, safety or fundamental rights, has the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision and the main elements of the decision.
Finally, Article 87 extends to AI Act infringements the rules on the reporting of breaches and the protection of whistleblowers set out in Directive (EU) 2019/1937.
Operational implication. Organisations using high-risk systems should set up internal channels to handle complaints and explanation requests, integrating them with data-subject rights under the GDPR and with existing whistleblowing procedures.
08Implementation timeline and key deadlines (Art. 113)
| Date | What becomes applicable |
| 1 August 2024 | Entry into force of Regulation (EU) 2024/1689 (20 days after publication in the Official Journal). |
| 2 February 2025 | Prohibitions on unacceptable-risk systems (Art. 5) and the AI Literacy obligation (Art. 4). |
| 2 August 2025 | Rules on GPAI models, the notifying authority and the EU governance structure. |
| 2 August 2026 | General application of the Regulation: Annex III high-risk systems, transparency obligations (Art. 50), and the national penalty regime in full effect. |
| 2 August 2027 | Obligations for Annex I high-risk systems (regulated products) and the alignment deadline for GPAI models already on the market before August 2025. |
The 2 August 2026 deadline directly concerns Annex III high-risk systems and transparency obligations: it is imminent, and it is advisable to have completed Phase 4 of the roadmap (Section 9), namely DPIA, FRIA and QMS, for systems classified as high risk before that date.
09Practical guide to corporate compliance
To build a sustainable compliance and risk-mitigation programme, the Compliance & Risk Management function can follow a 6-phase operational roadmap.
Phase 1, AI Discovery & Inventory
An up-to-date register of all software, algorithms and services in use or under development that embed AI components; identification of Shadow AI (generative-AI tools used without IT authorisation); qualification of the company's legal position for each system (provider, deployer, importer, distributor).
Phase 2, Risk triage & functional classification
Check whether the system falls among the prohibited practices (Art. 5, immediate decommissioning); whether it falls within the Annex III use cases (high-risk classification); whether it involves direct interaction with people or generates synthetic content (Art. 50 obligations); insert binding contractual clauses with providers for indemnity and a compliance guarantee.
Phase 3, AI Literacy programme (Art. 4)
Differentiated tracks: C-Level and board on risk governance, criminal/administrative liability and business impact; operational and HR teams on responsible AI use, bias identification and human-oversight procedures; IT and cybersecurity on data security, prompt-injection prevention and protection of trade secrets.
Phase 4, Integration of governance processes (DPIA + FRIA + QMS)
Drafting of the FRIA integrated with the DPIA; formal human-oversight procedures with named responsible individuals; configuration of automatic log retention and traceability for at least 6 months.
Phase 5, Alignment with ISO/IEC 42001 and ISO/IEC 27001
An Artificial Intelligence Management System (AIMS) integrated into the company's ISO architecture; a Statement of Applicability specific to AI metrics, certifying transparency, absence of bias and information security of the models, validating references as indicated in Section 7.2.
Phase 6, Continuous auditing and reporting
A cross-functional AI Ethics & Governance Committee (Legal, Compliance, DPO, CISO, Head of AI); periodic audits and adversarial simulations (red teaming) to test systems against cyber vulnerabilities and evolving discriminatory bias.
Final compliance checklist for the C-Level
- Registration and mapping of all AI systems active in the organisation.
- Verification that no applications fall under the absolute prohibitions (Art. 5).
- AI Literacy plan for employees and executives completed (Art. 4).
- Transparency notices prepared for chatbots and generative AI (Art. 50).
- FRIA and DPIA carried out for high-risk systems (HR, finance, access to services).
- Dedicated human-oversight operators defined and appointed (Art. 14).
- Log retention implemented for a minimum of 6 months.
- Path to ISO/IEC 42001 (AIMS) compliance started, with validation of the regulatory references as per Section 7.2.
- Monitoring of the approval process for the implementing decrees of Law 132/2025.
Conclusion
The EU AI Act radically reshapes the legal and operational landscape of the digital economy. For companies it is not only about avoiding the fines set out in Article 99, but about seizing the opportunity to stand out in the market: adopting certified Trustworthy AI models protects brand reputation, attracts responsible investors and ensures technological development that is secure and aligned with European ethical values.
Essential glossary
- GPAI (General Purpose AI)
- A general-purpose AI model, such as foundation models (LLMs, multimodal generators), subject to differentiated obligations depending on whether systemic risk is present.
- FRIA (Fundamental Rights Impact Assessment)
- An impact assessment on fundamental rights required before putting into service an Annex III high-risk system, for public bodies and entities providing public services.
- High-risk system
- An AI system that is a safety component of harmonised products (Annex I) or falls among the critical uses listed in Annex III, save for a documented exemption under Art. 6(3).
- AI Office
- A body established within the European Commission with direct supervisory and enforcement powers over GPAI model providers.
- AIMS (Artificial Intelligence Management System)
- An AI management system, formalised by the ISO/IEC 42001:2023 standard, useful for demonstrating compliance with the AI Act.